Join our Newsletter — 33% off our NHI Course

IGA implementation phases: where most programmes get stuck

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Most IGA programmes fail because teams sequence controls poorly, leaving half-implemented systems that auditors do not trust, according to Zluri’s phase-by-phase strategy on access reviews, lifecycle automation, granular entitlement control, identity security, and self-service requests. The practical lesson is that governance must start with visibility and ownership, then tighten access and automation in stages rather than trying to solve everything at once.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “How to Implement IGA in Your Organization: A Phase-by-Phase Strategy”.

Key questions

Q: What breaks when IGA is rolled out before access ownership is clear?

A: When ownership is unclear, reviewers cannot judge whether access is appropriate and remediation tasks stall.

Q: Why do access reviews fail so often in traditional IGA programmes?

A: They fail because reviewers are asked to judge technical entitlements without enough business context, so approval fatigue sets in and access gets rubber-stamped.

Q: How do organisations know whether their IGA programme is actually working?

A: Look for fewer orphaned accounts, fewer unresolved SoD conflicts, and a lower rate of redundant approvals in certification campaigns.

Practitioner guidance

  • Define application ownership first Assign a named owner to each high-value application so access reviews, approval decisions, and entitlement decisions have accountable humans behind them.
  • Start with access reviews on sensitive systems Begin with HR, finance, CRM, and identity platforms because they reveal the fastest compliance wins and the clearest visibility gaps.
  • Automate joiner-mover-leaver flows Connect authoritative HR attributes to identity provider provisioning and deprovisioning so role changes and exits update access without ticket delays.

Bottom line: IGA fails when teams implement controls in the wrong order and expect tooling to substitute for governance design.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

IGA fails when teams mistake periodic cleanup for governance. Access reviews are useful, but they are not a control model by themselves. They identify excess access after it exists, which means they cannot prevent drift between cycles or address systems that never enter the review scope. Practitioners should treat review outcomes as evidence for redesign, not as proof that access is inherently under control.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • 92% of organisations expose NHIs to third parties, which means lifecycle and ownership decisions often extend beyond internal IAM boundaries.

A question worth separating out:

Q: How can security teams tell whether self-service access is working?

A: Self-service is working when requests route to the right approvers, approvals are consistent with policy, and provisioning happens without bypass paths or shadow requests. If users still submit tickets outside the workflow or managers routinely override decisions, the process is creating friction instead of governed speed.

👉 Read our full editorial: IGA implementation needs phased governance, not a tool-first rollout



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Phased governance beats tool-first deployment because IGA is a sequencing problem before it is a tooling problem. The article correctly frames implementation as a dependency chain, not a product install. Access reviews create visibility, lifecycle automation removes drift, and entitlement governance tightens precision only after the earlier layers are stable. Practitioners should treat rollout order as a governance control in its own right.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations prioritise lifecycle automation before expanding self-service access?

A: Yes. Self-service only works when the access model already has clean role definitions, approval routing, and automated fulfilment behind it. If those foundations are missing, self-service speeds up bad decisions instead of good ones. Lifecycle automation should come first because it reduces drift and makes later request handling reliable.

👉 Read our full editorial: IGA implementation needs phased governance, not a tool-first rollout


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.